SOUND4 IMPACT
- <= 2
A conditional command injection vulnerability has been identified in SOUND4 IMPACT, FIRST, PULSE, and ECO products, specifically in versions through 2.x. This vulnerability allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can then execute commands by sending an HTTP POST request to the traceroute.php script, which activates the malicious file and removes it after execution.
Exploitation of this vulnerability could lead to unauthorized command execution on the affected system.
To reproduce this vulnerability, a local authenticated user can create a file in the /tmp directory with a .traceroute.pid extension, containing malicious commands. After the file is created, an external unauthenticated attacker can send a POST request to the traceroute.php script, which will execute the commands from the malicious file. The executed commands can include anything that the web server user has permission to run, such as accessing sensitive files or executing scripts that could compromise the system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.